Confidential computing's core trust mechanism is broken. The fix may not exist

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

New research from TU Dresden formally verifies that attested TLS, the protocol underpinning confidential computing's trust guarantees, is fundamentally broken. Using ProVerif, researchers found that all seven examined intra-handshake attestation binding mechanisms fail to prevent relay attacks, where a client verifies a genuine TEE but ends up sending encrypted data to a malicious machine. The flaw affects production systems including Meta's WhatsApp Private Processing, Edgeless Systems' Contrast, and Cocos AI (CVE-2026-33697, CVSS 7.5). The best available fix achieves only level-two binding, proving identity at handshake start but not during data transmission. Level-three binding, which would protect actual application traffic, may be architecturally impossible within intra-handshake attestation. Germany's BSI independently confirmed that confidential computing falls short of digital sovereignty claims. The researchers recommend abandoning intra-handshake attestation in favor of post-handshake attestation, and the IETF's SEAT working group has incorporated formal verification requirements into its charter. Vendor-dominated CCC working groups delayed publishing the vulnerability artifacts for over ten days despite repeated requests.

11m read timeFrom theregister.com
Post cover image
Table of contents
A protocol that promises more than it provesEurope built sovereign clouds to escape US control. Then forgot about the processorsEU sovereignty push gives tech buyers a new alphabet soup to swallowOne of Europe's sovereign cloud picks may not be so-sovereign after allNATO's battle for cloud sovereignty: Speed is existentialBSI reaches the same verdictAcknowledged everywhere except the sales pitchThe level that timing rules out
100 Impressions